Oktane26 was my 13th Oktane.
I was at the first one, when fewer than 500 people gathered around a young company and a big idea that identity would become a foundational layer of the cloud. I’ve watched every Oktane since from a different seat; first as Okta’s VP of Customer Success, then as co-founder of BeyondID as it became Okta’s first Diamond Partner, and now as part of KeyData Cyber, where identity, cybersecurity, governance and AI are converging into a single conversation.
This year in Las Vegas, the feeling in the halls was unmistakable. The momentum is back.
Identity didn’t get commoditized. AI made it bigger.
For a while, people asked whether identity would get absorbed into cloud platforms and security stacks. AI is proving the opposite. Every agent, workload, API and autonomous process is a new identity that has to be discovered, authenticated, authorized, governed and monitored.
And the human behind it matters more, not less. When an agent takes an action, we still need to know which human authorized it, what authority was delegated, what it can reach, what it actually did, and who is accountable.
Those are identity questions. Okta’s answer at Oktane was to position its platform as an identity security fabric spanning humans, machines and AI agents, with Auth0 carrying the same idea into customer and B2B experiences.
What mattered most
Agents become first-class identities
Okta for AI Agents now covers the full agent lifecycle: discover it, control its connections, watch what it does and shut it down. Agent SSO, Agent-to-Agent Connections and Resource Access Certifications are available today. Agent Gateway, which sits between an agent and every tool it calls, enforcing policy and logging each interaction rolls out next, followed by a runtime kill switch that can revoke every active token an agent holds, all targeted before the end of 2026.
The end of the API-key Wild West
Agent SSO brings Cross App Access to Okta’s SSO customers, replacing long-lived keys with short-lived, identity-governed tokens. Picture the future enterprise as Human → Agent → Agent → Application → API → Data. Every hop is a trust boundary, and identity has to travel with the transaction.
Governing agents, wherever your users live
Okta will now govern agents even when the human identity sits in another identity provider. That is the reality of every global enterprise I work with; Okta here, Entra there, acquired directories everywhere. Securing AI can’t wait for consolidation. Interoperability and open standards are the whole game.
Governance goes continuous
Automated Drift Detection & Remediation in Okta Identity Governance (early access targeted for Q4 2026) catches and revokes access that drifts from policy. Okta Privileged Access extends zero standing privilege to network devices, pipelines, workloads and agents (GA targeted for Q1 2027). And Permiso, which Okta closed on in August, brings threat detection across identity providers, clouds and SaaS.
Put together, that’s the real story. Authentication asks who you are. Authorization asks what you can do. Governance asks whether you should still be able to do it. Threat detection asks whether what you’re doing right now matches the trust we granted. In an agentic world, all four have to run continuously and together.
Customer identity goes agentic, too
Imagine telling an agent: “Find me the best flight, use my loyalty status, stay within travel policy and book it.” The merchant now has to establish whose agent this is, whether the customer authorized it, what it can buy and what it can be told. Auth0’s new commerce and B2B capabilities point at this shift, from authenticating a person at a login page to establishing delegated trust in an autonomous transaction.
Okta also formed the Blueprint Alliance with AWS, CrowdStrike, Databricks, Google Cloud, Salesforce, ServiceNow, Zscaler and others, turning the Blueprint for the Secure Agentic Enterprise, it first published in March into an open, multi-vendor reference architecture. It rests on four questions: Where are my agents? What can they do? What are they doing? How do I respond?
No single vendor will secure the agentic enterprise, and one gap is worth evaluating, the frontier-model makers aren’t members yet. An architecture like this is only as strong as its coverage of where agents actually run.
Responsible AI is an identity problem
Every board is talking about responsible AI: model governance, privacy, bias, safety, human oversight. All necessary. But you can’t govern an autonomous system if you can’t say who owns it, whose authority it’s using, what credentials it holds and what it did.
When Hugging Face disclosed in 2024 that some Spaces secrets may have been accessed, its response was to revoke tokens and move users to fine-grained access tokens. The lesson here is that credentials and least privilege matter far more when software can act on its own. A compromised human credential is dangerous, but a compromised autonomous identity operating across dozens of systems has a very different blast radius.
Where BeyondID and Okta go next
I helped customers adopt Okta from inside Okta. We built BeyondID because turning identity strategy into production takes deep expertise and today, as an Okta Apex Partner, a multiple-time AMER Partner of the Year and one of a small number of globally authorized Auth0 delivery partners, that is still the work.
Okta’s own leadership put it plainly: “Identity is the control plane for AI.” I agree. But the question clients bring us has changed. It used to be “How do we deploy Okta?” Now it’s “How do we build a secure, governed and responsible AI enterprise?” Our job is to turn what was announced at Oktane into production architecture:
- Discovering and governing human, machine and AI identities in one inventory
- Establishing trusted delegation between people and the agents acting for them
- Designing authorization for agents calling SaaS apps, APIs and MCP servers
- Implementing least privilege and zero standing privilege for agents and workloads
- Connecting governance to threat detection and response
That work is already in production.
“At Boston Medical Center, we partnered with Okta to deliver Epic-integrated identity; the kind of complex, regulated environment where the stakes for getting identity right are highest.”
Thirteen Oktanes in
Directories to federation. Passwords to passwordless. On-prem to cloud. Perimeter to Zero Trust. Access management to identity security. And now, human identity to human, machine and agent identity.
AI doesn’t replace the fundamentals. It raises the stakes on them: establish trust, authorize explicitly, apply least privilege, govern continuously, detect the abnormal, respond immediately.
The Identity Economy isn’t striking back because we’re returning to the IAM market of ten years ago. It’s striking back because the definition of identity is expanding. Every employee, customer, workload and machine has an identity. Now every AI agent needs one too and someone has to establish trust across billions of those interactions, decide what’s authorized, and shut it down when trust is broken.
That’s identity. After 13 Oktanes, I’m more convinced than ever that it has never mattered more.
Where are your agents? What can they reach? What can they do? How do I respond?
If you can’t answer those three questions today, start with a complimentary BeyondID AI Agent Discovery Workshop. In one week, we’ll inventory your agents, map their connections and deliver a governance roadmap built on Okta.




